Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rules problems ?

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 4 Posters 495 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      benbegr
      last edited by

      I don't understant what's wrong with my rules...
      I want to be able to communicate from the LAN to the other networks.
      here are the ping results:

      LAN HOST --> LAN GW = OK
      LAN HOST --> google = OK

      LAN HOST --> LABO (OPT2) GW = NOK
      LAN HOST --> LABO (OPT2) HOST = NOK

      LAN HOST --> IOT (OPT1) GW = NOK
      LAN HOST --> IOT (OPT1) HOST = NOK

      PFSENSE --> LABO (OPT2) HOST = OK
      PFSENSE --> IOT (OPT1) HOST HOST = OK

      LABO (OPT2) HOST --> OPT2 GW = OK
      LABO (OPT2) HOST --> LAN GW = OK
      LABO (OPT2) HOST --> LAN HOST = OK

      IOT (OPT1) HOST --> OPT1 GW = OK
      IOT (OPT1) HOST --> LAN GW = OK
      IOT (OPT1) HOST --> LAN HOST = OK

      Can you plz help me...I think my eyes are playing tricks on me...

      floating rules
      wan rules
      lan rules
      labo rules

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @benbegr
        last edited by

        @benbegr said in Firewall rules problems ?:

        I want to be able to communicate from the LAN to the other networks.

        You're already good.
        The default LAN rules, the ones you've found when installing pfSense, the ones you use right now, already permit you to connect to 'everywhere'.
        A ping from LAN to Labo, the pfSense interface IP, should reply.
        A host on Labo : check if that host actually replies to pings (coming from another network !).

        Can you show your LAN settings ? Labo settings ?

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        B 1 Reply Last reply Reply Quote 0
        • B
          benbegr @Gertjan
          last edited by benbegr

          @Gertjan said in Firewall rules problems ?:

          A ping from LAN to Labo, the pfSense interface IP, should reply.

          From the LAN, I can ping the LAN gateway and the internet, but I cannot ping the LABO gateway or a host on the LABO network. However, from the LABO network, I can ping everything.

          @Gertjan said in Firewall rules problems ?:

          Can you show your LAN settings ? Labo settings ?

          @Gertjan Thanks for your reply !

          Here are the LAN settings:
          LAN Settings
          And the LABO settings
          LABO Settings

          1 Reply Last reply Reply Quote 0
          • bmeeksB
            bmeeks
            last edited by bmeeks

            What kind of hardware are you running? Is it a Netgate appliance, and if so, which one?

            I ask because in your LAN settings screenshot I see VLAN 4091. That is usually one of the special VLAN IDs reserved for the Marvell switch inside certain Netgate appliances. Setting the correct VLAN configuration is critical for the Marvell switch devices as the "ports" you see exposed are not truly individual hardware ports. They are simply ports connected to a common SOC (system on a chip) Ethernet switch. VLANs are configured internally on that Marvell switch to produce psuedo individual ports (LAN, OPT1, OPT2, etc.). And adding a LAGG on top of that doubly complicates things ☺.

            B 1 Reply Last reply Reply Quote 0
            • B
              benbegr @bmeeks
              last edited by

              @bmeeks Thank you for your reply! Yes, it is a Netgate 7100.
              Here's how the VLANs are configured:
              alt text
              alt text
              alt text
              alt text

              bmeeksB 1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks @benbegr
                last edited by bmeeks

                @benbegr:
                I've not configured an XG-7100, so I'm no expert on setting up the Marvell switch. I assume you have read through all the documentation available here: https://docs.netgate.com/pfsense/en/latest/solutions/xg-7100-1u/configuring-the-switch-ports.html and here: https://docs.netgate.com/pfsense/en/latest/solutions/xg-7100-1u/switch-overview.html.

                Tagging @stephenw10 here as he is the Netgate hardware expert. He should see the tag and weigh in soon.

                1 Reply Last reply Reply Quote 0
                • M
                  mvbif
                  last edited by

                  @benbegr said in Firewall rules problems ?:

                  LAN HOST --> LABO (OPT2) GW = NOK
                  LAN HOST --> LABO (OPT2) HOST = NOK

                  LAN HOST --> IOT (OPT1) GW = NOK
                  LAN HOST --> IOT (OPT1) HOST = NOK

                  O_o sound strange,cloud have any sense only in case of static route on lan host. But would cause no reply to others too.
                  All the gw are pfsense interfaceses right? The rules is not the issue, as per above you have almost all vs all .
                  I would follow with packet capture from pfsense gui, packets from host lan, first on lan interface then on dest interface. Just in case a tracert too from host lan.
                  Is there any nat rules? Secondary nic on lan host, with a lan overlapping?

                  B 1 Reply Last reply Reply Quote 0
                  • B
                    benbegr @mvbif
                    last edited by

                    Your comment gave me the bug..., I double-checked my LAN host conf and found out that on the LAN host, there was a static route that was sending packets to the LABO network using the wrong gateway... I'm really sorry to have taken your time for such a stupid thing... thank you very much for your time and your help...

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.